- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello.
I'm trying to use a 3rd party wildcard certificate for GAIA portal access to some of our firewalls. A CP engineer and I installed wildcard.key file as server.key and the .crt file as server.crt but the IP was still resolving to the ISP domain name so it was giving a domain mismatch error.
I got that fixed and now the ip resolves to our domain but the website still shows an error and says that the domains do not match.
I got a new engineer who says we have to do a CSR for each gateway and cannot use the wildcard certificate.
Is this the case or were we just not communicating?
You can use the SAN to create multiple FQDN and IP address matches so a single cert works for the cluster. See https://support.checkpoint.com/results/sk/sk170395. Note it only shows DNS options for FQDN, but you can also use IP options for IP address in case you go to the portal via IP. Example:
subjectAltName = @VPN_names
[vpn_names]
DNS.1 = www.abc.com
DNS.2 = abc.com
DNS.3 = sub.abc.com
DNS.4 = sub2.abc.net
IP.1 = 172.25.105.136
IP.2 = 172.25.105.134
As far as I know, this is supported.
Are you accessing the Gaia WebUI by FQDN?
Im fairly positive you can use wildcard cert, had seen customers do it before.
Andy
Do you use a IP-address for the gateway? That's not possible. The wildcard just includes domains. There is not wildcard IP-address certificate. You have to use FQDN.
If you are wanting to change the GAIA portal certificate - you want to use the Platform Portal section of the Gateway Properties to change the certificate. Don't manually change the files at the CLI. I think it is possible to edit the files, then restart the service, but with the multiportal it is easier to do it this way. Just don't forget to install the policy after making the change.
And when it's in a cluster you use the internal VIP for the FQDN. However, since the VIP FQDN of a member is a different ip then the VIP you still get a warning. Not to mention the standby member... Also, there is no portal platform section on a manager. For the manager you must need to trust the CP ICA to your browsers trusted CAs store.
You can use the SAN to create multiple FQDN and IP address matches so a single cert works for the cluster. See https://support.checkpoint.com/results/sk/sk170395. Note it only shows DNS options for FQDN, but you can also use IP options for IP address in case you go to the portal via IP. Example:
subjectAltName = @VPN_names
[vpn_names]
DNS.1 = www.abc.com
DNS.2 = abc.com
DNS.3 = sub.abc.com
DNS.4 = sub2.abc.net
IP.1 = 172.25.105.136
IP.2 = 172.25.105.134
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY